Executive brief
MATCHA INVOICE, an invoicing and billing management software, contains a security flaw that allows an administrative user to upload dangerous files to the server. If exploited, an attacker with administrative access could take full control of the server, potentially leading to the theft of sensitive financial data or a complete service shutdown. Organizations using version 2.6.6 or earlier should update to the latest version immediately to prevent unauthorized code execution.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in ICZ Corporation MATCHA INVOICE versions 2.6.6 and earlier. The flaw allows a remote attacker with administrative privileges to upload arbitrary PHP files to the server. Because the application fails to properly validate file types or restrict upload locations, the attacker can execute these files to achieve arbitrary code execution (RCE) and gain full system control. The vendor has released version 2.6.7 to address this issue.
Affected products
- ICZ Corporation MATCHA INVOICE 2.6.6 and earlier
Timeline
- 2026-04-07: patched: Vendor released version 2.6.7 to address the vulnerability.
- 2026-04-08: disclosed: Initial disclosure via JVN and NVD.